Security

Splunk LDAP to AD Auth Fails if AD server is IPv6-based

kindlund
New Member

Problem: Enabling Splunk LDAP authentication to an Active Directory server fails, if IPv6 is enabled on the server and tries to connect to the Active Directory server over an IPv6 address.

During this time, logging in using AD credentials either take 30 mins (very long time) or fails completely.

The workaround is to make sure you specify the IPv4 address of the Active Directory explicitly within Splunk. If you specify the DNS entry of the Active Directory, make sure when Splunk does an nslookup on the IP, that it doesn't use an IPv6 address.

FYI.

0 Karma

ithangasamy_spl
Splunk Employee
Splunk Employee

IPv6 support is available only from Splunk 4.3 release onwards, you should not see this problem in 4.3, if you do, to debug try disabling the referrals it could be the referrals issue

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...